{"id":"CVE-2026-50884","aliases":["GHSA-5442-mh7f-72px"],"title":"statping-ng allows attackers to escalate privileges to Administrator and access sensitive components","summary":"statping-ng allows attackers to escalate privileges to Administrator and access sensitive components","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"statping-ng","product":"github.com/statping-ng/statping-ng","ecosystem":"go","affected":["github.com/statping-ng/statping-ng <= 0.93.0"],"published":"2026-06-15","updated":"2026-08-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5442-mh7f-72px","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50884"},{"url":"https://gist.github.com/pyuysig/72acb62a9973fa394581f662c0f12704"},{"url":"https://github.com/statping-ng/statping-ng"}],"tags":["osv","go"],"epss":0.00417,"epssPercentile":0.33292,"ingestedAt":"2026-08-27T19:27:46.267Z","slug":"CVE-2026-50884","body":"## Overview\n\nIncorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.\n\n## Affected packages\n\n- `github.com/statping-ng/statping-ng <= 0.93.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}